CyberRota Analysis
AI-GeneratedThe Jenkins SAML Plugin versions 4.618.v441a_27fa_46d2 and earlier are vulnerable to an attack that enables the overwriting of the SAML identity provider metadata file via Stapler data binding. This flaw allows attackers to substitute the metadata with malicious content, potentially enabling them to authenticate as any user within the Jenkins environment. Organizations using this plugin should prioritize remediation to mitigate the risk of unauthorized access.
Original NVD Description
Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.